Vous êtes sur la page 1sur 2

CreateRestorePoint:

CloseProcesses:
2017-01-06 21:24 - 2017-01-06 21:24 - 00250912 _____ C:\Windows\SysWOW64\kz.exe
2017-01-06 21:18 - 2017-01-08 13:44 - 00000000 ____D C:\Users\Usuario\AppData\L
ocal\SaFiSvc
2017-01-06 21:15 - 2017-01-08 13:44 - 00000000 ____D C:\Users\Usuario\AppData\L
ocal\AdvinstAnalytics
2017-01-06 18:17 - 2017-01-06 18:17 - 00000000 ____D C:Users\Usuario\AppData\Lo
cal\UCBrowser
2017-01-06 18:15 - 2017-01-06 18:15 - 00000000 ____D C:\Users\Default\AppData\L
ocal\AdvinstAnalytics
2017-01-06 18:15 - 2017-01-06 18:15 - 00000000 ____D C:\Users\Default User\AppD
ata\Local\AdvinstAnalytics
2017-01-06 18:14 - 2017-01-06 18:14 - 00000000 ____D C:\Windows\SysWOW64\sstmp
2017-01-06 18:14 - 2017-01-06 18:14 - 00000000 ____D C:\Windows\system32\sstmp
2017-01-06 22:02 - 2016-08-26 21:08 - 00000000 ____D C:\Users\Usuario\AppData\L
ocal\Idsoft
2017-01-06 22:02 - 2016-08-19 13:03 - 00000000 ____D C:\Users\Usuario\AppData\L
ocal\{C68FF034-E3DD-9D42-88EB-BA90543947AE}
2017-01-06 22:02 - 2016-08-19 13:02 - 00000000 ____D C:\Users\Usuario\AppData\L
ocal\YWLPack
Task: {5679CD77-62B6-4A95-B09B-84E825212864} - System32\Tasks\{1EEAE3ED-8711-AE8
9-FD30-05831B235553} => C:\Users\Usuario\AppData\Local\{C68FF~1\PRODUC~1.EXE <==
== ATTENTION
WMI_ActiveScriptEventConsumer_ASEC: <===== ATTENTION
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start M
enu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplor
e.exe (Microsoft Corporation) -> hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start M
enu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplor
e.exe (Microsoft Corporation) -> hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explor
er\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Applic
ation\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Usuario\AppData\Lo
cal\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explor
er\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Applic
ation\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Usuario\AppData\Lo
cal\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explor
er\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\In
ternet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explor
er\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86
)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://qtipr.com/
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Googl
e Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Goo
gle Inc.) -> --load-extension="C:\Users\Usuario\AppData\Local\kemgadeojglibflom
icgnfeopkdfflnk" hxxp://qtipr.com/
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozil
la Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Co
rporation) -> hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Fi
les (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extensio
n="C:\Users\Usuario\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr
.com/
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program
Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://qtipr.co
m/
GroupPolicy: Restriction - Chrome <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:

Vous aimerez peut-être aussi